Gadget News

AI Image, for illustration purposes

If you searched for “LastPass Authenticator download” and landed on a shiny GitHub page with LastPass branding and fake “VirusTotal Approved” badges, do not run that ZIP. Researchers from LastPass’s TIME team and Delphos Labs say those fake repos delivered a Windows installer that first kills antivirus from kernel mode, then runs an information stealer LastPass tracks as Rapuncel. The joint report landed mid-September 2026 (BleepingComputer covered it Sept 18; The Hacker News Sept 21).

Here is the consumer version of the chain. The ZIP side-loads a malicious DLL through a renamed Microsoft debugger binary. That installs a third-party kernel driver researchers call Alinubx.sys, written to look NVIDIA-ish (nvfsflt64.sys, service NvFsFilter).

The driver is signed through Microsoft’s Windows Hardware Compatibility Publisher pipeline. Attestation is not safety: it still carried a kill list of 145 AV and EDR process names. With defenses down, Rapuncel empties browser password stores (25 browsers), roughly 30 crypto wallets, Discord/Steam/Telegram sessions, Windows Credential Manager, and sensitive files whose names scream password/seed/wallet.

The same kit reportedly wore skins for at least 40 brands. LastPass was one lure among many, first spotted Aug 13, 2026.

Two facts people will often get wrong online.

1/ This is brand impersonation. LastPass says no LastPass systems, services, or customer vaults were involved or compromised.

2/ The real LastPass Authenticator is a phone MFA app, not a fat Windows ZIP from GitHub. Get it from the Apple App Store or Google Play, or via lastpass.com. There is no official installer on GitHub.

If you already ran the fake file, treat that PC as kernel-compromised. From a different, clean device, change passwords, revoke sessions, and move crypto off any exposed seeds or wallet files. On-box antivirus may keep dying after reboot because the driver comes back. Prefer Safe Mode / offline cleanup, or rebuild. Do not rotate important credentials while still using the infected machine.

We expect search ads and SEO fakes for “authenticator download” to keep recycling this kit. Type the store yourself. If the download is a huge Windows ZIP claiming to be LastPass Authenticator, close the tab.

Fake LastPass Authenticator Can Kill Your Antivirus. Take This Action

, original content from Ubergizmo. Read our Copyrights and terms of use.

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.